Patch-ID# 114819-07


Download this patch from My Oracle Support

Your use of the firmware, software and any other materials contained in this update is subject to My Oracle Support Terms of Use, which may be viewed at My Oracle Support.
For further information on patching best practices and resources, please see the following links:
Copyright (c) 2012, Oracle and/or its affiliates. All rights reserved.

Keywords: security gnome libpng graphics tex
Synopsis: GNOME 2.0.0_x86: libpng Patch
Date: Oct/03/2008


Install Requirements: NA

Solaris Release: 9_x86

SunOS Release: 5.9_x86

Unbundled Product: GNOME

Unbundled Release: 2.0.0_x86

Xref: This patch available for SPARC as 114818

Topic:

Relevant Architectures: i386

Bugs fixed with this patch:

Sun CR # Bug #
480908715143342
488163915165089
490182215171290
497946015192455
501969915203119
507522715219072
655590015396092


Changes incorporated in this version: 6555900

Patches accumulated and obsoleted by this patch:

Patches which conflict with this patch:

Patches required with this patch:

Obsoleted by:

Files included with this patch:

/usr/lib/pkgconfig/libpng.pc
/usr/lib/pkgconfig/libpng12.pc
/usr/sfw/bin/libpng-config
/usr/sfw/bin/libpng12-config
/usr/sfw/include/libpng
/usr/sfw/include/libpng12/png.h
/usr/sfw/include/libpng12/pngconf.h
/usr/sfw/include/png.h
/usr/sfw/include/pngconf.h
/usr/sfw/lib/libpng.so
/usr/sfw/lib/libpng.so.2
/usr/sfw/lib/libpng.so.2.1.0.15
/usr/sfw/lib/libpng.so.3
/usr/sfw/lib/libpng.so.3.1.2.5
/usr/sfw/lib/libpng10.so
/usr/sfw/lib/libpng10.so.0
/usr/sfw/lib/libpng10.so.0.1.0.15
/usr/sfw/lib/libpng12.so
/usr/sfw/lib/libpng12.so.0
/usr/sfw/lib/libpng12.so.0.1.2.5
/usr/sfw/share/man/man3/libpng.3 (deleted)
/usr/sfw/share/man/man3/libpngpf.3 (deleted)
/usr/sfw/share/man/man5/png.5 (deleted)

Problem Description:

6555900 libpng: needs to be upgraded due to security vulnerability (DoS to linking apps), 
        CERT VU#684664
 
(from 114819-06)
 
5075227 multiple vulnerabilities in the libpng [CAN-2004-0597]
 
(from 114819-05)
 
5019699 libpng12.pc has invalid prefix value which causes build failure when used
 
(from 114819-04)
 
4979460 patches 114818-03 & 114819-03 causing S9U6 nightly build failures
 
(from 114819-03)
 
4901822 tetex 2.0.2 needs libpng 1.2.5 version for correct rendering of png images within tex documents
 
(from 114819-02)
 
4881639 Gnome patch 114819-01 fails to install for Solaris 9 MU4
 
(from 114819-01)
 
4809087 libpng buffer overflow


Patch Installation Instructions:
--------------------------------
Refer to the man pages for instructions on using 'patchadd' and 'patchrm'
scripts provided with Solaris.  Any other special or non-generic
installation instructions should be described below as special
instructions.  The following example installs a patch to a standalone
machine:
 
	example# patchadd /var/spool/patch/104945-02
 
The following example removes a patch from a standalone system:
 
	example# patchrm 104945-02
 
For additional examples please see the appropriate man pages.


Special Install Instructions:
-----------------------------
 
NOTE 1:  To get the complete fix for bugID 6555900 (libpng: needs to be 
         upgraded due to security vulnerability, DoS to linking apps, 
         CERT VU#684664), please also install the following patch: 
 
         139383-01 (or greater)  GNOME 2.0.2: libpng patch


README -- Last modified date: Saturday, November 10, 2012